Description
Allowing insecure cipher suites can weaken protection even when TLS is enabled. Remove suites classified as insecure by the supported version from API server and kubelet configurations.
Omitting a cipher list uses implementation defaults and does not itself mean weak encryption. This setting does not control TLS 1.3 cipher suites.
Potential impact
- Negotiating an insecure suite can weaken protection of encrypted traffic.
- Retaining only unsupported suites can prevent legitimate clients from connecting.
Remediation
- Select suitable suites such as AES-GCM or ChaCha20-Poly1305 from your version’s recommended list.
- Review the minimum TLS version, certificate type and client compatibility together.
- Test actual TLS negotiation and normal connectivity, and verify that insecure suites are not accepted.
Examples
These excerpts separately show kubelet and historical API server cipher arguments. They are not a complete replacement for the same process; use your actual version, certificates and execution image.
Before
apiVersion: v1
kind: Pod
metadata:
name: command-demo
spec:
containers:
- name: command-demo-container
image: foo/bar
command: ["kubelet"]
args:
[
"--tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256,TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256"
]
TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256 is allowed. The current Kubernetes reference classifies this suite as insecure.
After
apiVersion: v1
kind: Pod
metadata:
name: command-demo
spec:
containers:
- name: command-demo-container
image: gcr.io/google_containers/kube-apiserver-amd64:v1.6.0
command: ["kube-apiserver"]
args:
[
"--tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256"
]
AES-GCM suites are specified. Verify support in your version, serving certificate and clients.